Sensitive data spills from more than 16,000 cloud databases
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 29th, 2026.
Sensitive records were left readable in more than sixteen thousand misconfigured Supabase databases. More than half exposed personally identifiable information, while a smaller group included passwords or authentication tokens. The examples included a Canadian immigration service with 884 plaintext passwords and a government consulate with records belonging to twenty five thousand people. AI-assisted development accounts for more than sixty percent of newly created databases, although the scan did not establish that every affected site was built with AI.
The business risk is straightforward. An exposed backend can turn a quickly launched application into a long-term privacy, identity, and trust problem. Rapid development still needs clear ownership, data classification, and release controls. Defenders should test row-level security, examine public access paths, and search database tables for credentials before production release. Generated configurations also need human verification because an AI tool may not apply secure defaults. The larger lesson is that development speed magnifies basic configuration failures. Audit every Supabase project for effective row-level security, exposed public keys, readable sensitive tables, and plaintext credentials before release.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.